PT-2026-81356 · Pypi · Nltk

·

CVE-2026-79675

·

Published

2026-08-25

·

Updated

2026-09-01

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions NLTK versions prior to 3.10.3
Description Insufficient validation of JVM options passed through the options parameter in the java() function allows the injection of dangerous JVM flags. By supplying malicious options such as -agentpath, -javaagent, or @argfile to Stanford wrapper classes, an attacker can achieve arbitrary code execution.
Recommendations Update to version 3.10.3 or later. As a temporary mitigation, restrict or avoid passing untrusted input to the options parameter of the java() function.

Exploit

Fix

Argument Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-79675
ECHO-8A7E-A35B-937A
GHSA-3H2G-J4WP-7QQQ
GHSA-M4RF-3FR8-XWX3
PYSEC-2026-3749

Affected Products

Nltk